CVE-2026-76962
Received Received - Intake

Authorization Bypass in SAP S/4HANA Manage Bank Chains

Vulnerability report for CVE-2026-76962, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-08

Assigner: SAP SE

Description

SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send specially crafted requests to delete specific entries that should not be accessible to them. This results in a low impact on availability. There is no impact on confidentiality and integrity.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-08
Generated
2026-09-08
AI Q&A
2026-09-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sap s_4hana *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in SAP S/4HANA's Manage Bank Chains app allows low-privileged attackers to delete specific entries by sending crafted requests. The issue stems from insufficient authorization checks in the app's functionality.

Detection Guidance

Detecting this vulnerability requires checking SAP S/4HANA systems for unauthorized deletion requests in the Manage Bank Chains app. Review application logs for unusual DELETE operations targeting sensitive entries. Ensure proper authorization checks are enforced in the app's functionality.

Impact Analysis

An attacker could exploit this to delete entries they shouldn't access, causing low impact on system availability. Confidentiality and integrity of data remain unaffected.

Compliance Impact

This vulnerability has a low impact on availability but does not affect confidentiality or integrity. It may not directly violate GDPR or HIPAA, but unauthorized data deletion could raise concerns under principles requiring integrity and availability of personal or health data.

Mitigation Strategies

Apply the official SAP security note 3657599 to patch the authorization check flaw in the Manage Bank Chains app. Ensure low-privilege users cannot send crafted requests to delete unauthorized entries.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76962. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart